Data Protection Addendum
This Data Protection Addendum (“Addendum”) forms part of the Terms of Service between Miracle Advance Technologies Co., Ltd. (“Miracle Advance”) and the Customer. It governs the Customer’s access to and use of Miracle Advance’s services (“Services”). This addendum reflects Miracle Advance’s commitment to data protection and privacy, which aligns with our privacy policy.
Definitions
- Affiliate: Any entity that controls, is controlled by, or is under common control with either Customer or Miracle Advance, where “control” refers to the power to direct management and policies, whether through ownership, contract or otherwise.
- Customer Personal Data: Personal Data provided by or made available by the Customer to Miracle Advance, or collected by Miracle Advance on behalf of the Customer, which is processed to perform the Services.
- Data Protection Laws: Any local, state, or national laws regarding the processing of Personal Data applicable to Miracle Advance in the jurisdictions where Services are provided, including privacy, security, and data protection laws.
- Security Incident: Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Miracle Advance.
- Services: According to the Agreement, Miracle Advance supplies the services to the Customer or the Customer’s Affiliates.
- Third Country: Countries that have yet to receive an adequacy decision from an applicable authority relating to cross-border data transfers of Personal Data, including regulators such as the European Commission.
The terms “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processor,” and “Supervisory Authority” have the meanings ascribed to them in applicable Data Protection Laws.
Scope of Addendum
This Addendum applies to Miracle Advance’s processing of Customer Personal Data under the Agreement to the extent such processing is subject to Data Protection Laws.
Types of Personal Data:
- Identity Data (name, title, position)
- Contact Data (email, phone, address)
- Technical Data (IP address, login data, device information)
- Usage Data (service usage patterns, preferences)
Categories of Data Subjects:
- Customer’s employees
- Customer’s end users
- Customer’s clients
Roles of the Parties
The Parties acknowledge that:
- The customer acts as a Controller.
- Miracle Advance acts as a Processor.
- Both parties shall comply with their respective obligations under Data Protection Laws.
Data Protection Officer
Appointment
Miracle Advance has appointed a Data Protection Officer (“DPO”) to oversee compliance with Data Protection Laws and this Addendum.
The Customer must determine whether it must appoint a DPO under applicable Data Protection Laws.
DPO Contact Details
Name/Title: S M Al Shahaneaz Shaikat – Data Protection Officer (DPO)
Email: shahaneaz@miracleadvance.com
Responsibilities
The DPO oversees Miracle Advance’s data protection strategy and ensures compliance with Data Protection Laws and this Addendum.
The DPO shall serve as a point of contact for supervisory authorities and Data Subjects regarding the processing of Customer Personal Data.
Data Processing Terms
Customer Obligations:
- Ensure a lawful basis for processing
- Provide documented instructions
- Comply with Data Protection Laws
- Maintain accurate records
Miracle Advance Obligations: Miracle Advance shall:
- Process Customer Personal Data solely on documented instructions from the Customer, to provide the Services and as necessary to perform its obligations under the Agreement.
- Implement and maintain appropriate technical and organizational measures to ensure security appropriate to the risk of processing Customer Personal Data.
- Ensure that personnel authorized to process Customer Personal Data are committed to confidentiality.
- Notify the Customer without undue delay upon becoming aware of a Personal Data Breach involving the Customer’s Personal Data.
- Where possible, assist the customer in responding to data subject requests and ensure compliance with obligations under applicable data protection laws.
- Upon termination or expiry of the Agreement, the Customer may choose to delete or return all Customer Personal Data unless retention is required by applicable law.
Sub-processors
The Customer agrees that Miracle Advance is authorized to engage Sub-processors to process Customer Personal Data, provided that:
- Miracle Advance notifies the Customer of any intended changes concerning the addition or replacement of Sub-processors.
- Miracle Advance imposes data protection obligations on sub-processors like those set out in this addendum.
- Miracle Advance remains liable for any failure by sub-processors to fulfill their obligations to process customer personal data.
Data Subject Rights
Response Procedures:
- Forward requests to Customer within two business days
- Assist Customer in responding within 30 days
- Maintain records of all requests
- Implement technical measures to facilitate responses
Cost Allocation:
- Routine assistance at Miracle Advance’s cost
- Extensive assistance at the Customer’s cost
- Cost estimates provided in advance
Security Measures
Technical Measures:
- Encryption at rest and in transit
- Access control and authentication
- Firewalls and intrusion detection
- Regular security updates
- Backup and recovery procedures
Organizational Measures:
- Regular staff training
- Access on a need-to-know basis
- Security policies and procedures
- Regular security assessments
- Incident response plan
International Data Transfers
Transfer Mechanisms:
- Standard Contractual Clauses
- Binding Corporate Rules
- Adequacy decisions
- Additional safeguards as required
Transfer Impact Assessments:
- Regular assessments of recipient countries
- Documentation of safeguards
- Updates as required by law
Audit Rights
Customer Rights:
- Annual audit with 30 days notice
- Additional audits for cause
- Access to relevant documentation
- Third-party audit reports
Audit Process:
- Scope agreement
- Confidentiality requirements
- Cost allocation
- Report sharing
Data Breach Response
Notification Timeline:
- Initial notification within 24 hours of discovery
- Detailed report within 72 hours
- Regular updates as new information becomes available
Notification Contents:
- Nature of the breach
- Categories of data affected
- Approximate number of data subjects affected
- Likely consequences
- Measures taken or proposed
- Contact point for information
Term and Termination
Duration:
- Coterminous with the main Agreement
- Survival of specific obligations
Termination Actions:
- Return or deletion of data
- Certification of deletion
- Retention, if legally required
Liability and Indemnification
Liability:
- Cap at [amount] per incident
- Unlimited for willful misconduct
- Exclusions from limitation
Insurance:
- Required coverage types
- Minimum coverage amounts
- Evidence of Coverage
Governing Law
This Addendum is governed by the Agreement’s governing law unless otherwise required by Data Protection Laws.
Miscellaneous
If any provision of this Addendum is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.
For any inquiries regarding this Addendum, please contact us at:
Miracle Advance Technologies Co., Ltd.
2521/34 Ladprao Road, Khlongchaokhunsing, Wangthonglang, Bangkok 10310, Thailand
Email: info@miracleadvance.com
Phone: +66 2514-0314-7
Annex 1 to Data Protection Addendum
Description of Processing Activities for Customer Personal Data
This Annex outlines the details of the processing of Customer Personal Data by Miracle Advance Technologies Co. Ltd. in connection with the Services.
List of Parties
Data Exporter
| Name | Customer (as defined in the Agreement) |
| Address | As specified in the relevant Order Form. |
| Contact person’s name, position, and contact details | As specified in the relevant Order Form. |
| Activities relevant to the data transferred under these Clauses | As specified in the relevant Order Form. |
| Contact person’s name, position, and contact details | Recipient of Services Miracle Advance Technologies Co. Ltd. provided following the Agreement. |
| Signature and date | The signature and date are outlined in the Agreement. |
| Role (controller/processor) | Controller |
Data Importer
| Name | Miracle Advance Technologies Co. Ltd. |
| Address | 2521/34 Ladprao Road, Khlongchaokhunsing, Wangthonglang, Bangkok 10310, Thailand |
| Contact person’s name, position, and contact details | Mostafa Chowdhury, Co-founder, msac@miracleadvance.com |
| Activities relevant to the data transferred under these Clauses | The provision of Services to the Customer is under the Agreement. |
| Signature and date | The signature and date are outlined in the Agreement. |
| Role (controller/processor) | Processor |
Competent Supervisory Authority
- Supervisory Authority: As determined in accordance with Clause 13 of the EU SCCs.
Processing Information
- Categories of data subjects: Customer’s authorized users of the Services.
- Categories of personal data transferred:
Automatically processed by the Services (provided by customers or authorized users in connection with audit services provided by Miracle Advance Technologies):
- Names
- Email IDs
- Address
- Date of Birth
- Employment details
- Sensitive personal data transferred: None
- Frequency of transfer: Continuous
- Nature of processing:
The processing includes providing the Services described in the Agreement and order forms. This includes querying, cleansing, standardizing, enriching, and securely storing Customer Personal Data. - Purpose of data transfer and processing:
Facilitate performance of the Services in accordance with the Agreement. - Business Purposes for Processing (For California consumers under CCPA):
- Helping ensure security and integrity.
- Debugging to identify and repair functionality errors.
- Performing services on behalf of the business (e.g., account maintenance, analytics, storage).
- Internal research for technological development and demonstration.
- Verification/maintenance of service or device quality and safety.
- Retaining subcontractors meeting CCPA service provider standards.
- Service quality improvement provided no cross-purpose data use.
- Prevention, detection, and investigation of data security incidents.
- Retention Period: As outlined in the Agreement, Addendum, and related order forms.
- Subprocessor Transfers: Details on subject matter, nature, and duration of processing are provided in the Agreement.
Technical and Organizational Security Measures
1. Security Management
- Designated Security Personnel: Oversight of an Information Security Program.
- Policies and Assessments: Annual reviews, third-party risk assessments, penetration testing, and patch management.
2. Personnel Security
- Background checks, confidentiality agreements, and privacy/security training for all personnel accessing Customer Personal Data.
3. Access Controls
- Formal access management with periodic reviews.
- Multi-factor authentication (MFA) and single sign-on (SSO) are required for system access.
4. Data Center and Network Security
- Regular vulnerability scans, disaster recovery testing, and security monitoring.
- HTTPS encryption for data in transit and encryption for data at rest.
5. Incident Management
- Defined escalation and incident response procedures for security breaches.
Annex 2: Sub-processors
| Name of Sub-Processor | Description of Processing | Location |
| Google Workspace | Email services | USA |
| SmartTask | Work management | USA |
| GitHub | Code version control | USA |
| Line | Messaging | Japan |
| UIH | Infrastructure Hosting | Thailand |